Autolus is a biopharmaceutical company spun out of University College London in 2014, developing programmed T cell therapies for cancer and autoimmune diseases. The company's core technical work centers on T cell programming and Chimeric Antigen Receptors (CAR T), designing autologous cellular therapies that engineer a patient's own immune cells to recognize and attack disease. Their research has been published in the New England Journal of Medicine and Nature Medicine, with a clinical pipeline now anchored by an FDA-approved product.
In November 2024, the FDA approved AUCATZYL (obecabtagene autoleucel, obe-cel) for adults with relapsed or refractory B-cell acute lymphoblastic leukemia. That approval marks a concrete operational milestone - moving from research-stage programming to a commercial-stage biologic with all the manufacturing, quality, and regulatory infrastructure that implies. Autolus maintains presence across London, Germany, and the USA.
For cybersecurity professionals, the threat surface here is the intersection of biologics manufacturing and sensitive patient data. Autolus operates in a regulated environment handling personal health information, proprietary cell therapy processes, and clinical trial data - domains subject to HIPAA, GDPR, and FDA 21 CFR Part 11 compliance. The attack model includes protecting manufacturing execution systems, securing chain-of-custody data for autologous therapies where a mix-up is a patient-safety event, and defending intellectual property around T cell programming techniques that represent years of research investment. The stakes are not abstract: in personalized cell therapy, data integrity and system availability are directly coupled to patient outcomes.






